ThinkMo CCIE EI Lab v1.0 Module1 Version 4.2 Resource Design Ignore PDF
ThinkMo CCIE EI Lab v1.0 Module1 Version 4.2 Resource Design Ignore PDF
Total 39 Questions
QUESTION 1
Welcome to the FABD2 company!
Please read all the available resources before starting the scenario by
QUESTION 2
Refer to the new resource(s) available.
Solution
Answer: c
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 3
Refer to the new resource(s) available.
Based on the description of the issue, what is the most likely reason?
a) Rapid PVST+ requires the use of LACP fast rate to support rapid convergence on
EtherChannels.
b) Trunk ports are not considered as edge ports unless explicitly configured to.
c) The MAC aging time needs to be set to a value shorter than
max_age+forward_delay.
d) PortFast is not enabled globally on the switches.
Solution
Answer: b
QUESTION 4
Refer to the new resource(s) available.
Based on the diagram, what design change can be made to address the flapping
EIGRP neighbor
between r24 and r70 without impacting the network connectivity to any other
DMVPN location?
a) On r70, enable EIGRP stub
b) On r21 and r70, put the WAN interfaces toward the SP into a front door VRF
c) On r70, only enable EIGRP on the r70 LAN interfaces and the DMVPN tunnel
d) On r70, do not advertise the 10.200.0.0/24 subnet in BGP
e) On r70, put the WAN interfaces toward the SP into a front door VRF
Solution
Answer: c
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 5
Refer to the new resource(s) available.
For each of the EtherChannel types, indicates whether the individual statement are
true, if any (select all that apply)
Type of EtherChannel
Statement LACP Static
EtherChannel EtherChannel
Provides the shortest link bundling time possible
Adds data plane overhead
Adds control plane overhead
Provides protection against miscabling
Allows automatic fallback to individual link operation
Provides the widest vendor and implementation
interoperability
Supports Layer3 EtherChannels
Supports Layer2 EtherChannels
Provides protection against misconfiguration
Supports various load balancing modes
Solution
Type of EtherChannel
Statement LACP Static
EtherChannel EtherChannel
Provides the shortest link bundling time □ √
possible
Adds data plane overhead □ □
Adds control plane overhead √ □
Provides protection against miscabling √ □
Allows automatic fallback to individual link √ □
operation
Provides the widest vendor and implementation √ □
interoperability
Supports Layer3 EtherChannels √ √
Supports Layer2 EtherChannels √ √
Provides protection against misconfiguration √ □
Supports various load balancing modes √ √
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 6
Refer to the new resource(s) available.
What is the appropriate way to ensure that VXLAN-encapsulated traffic is properly
load-balanced across
physical member links of an EtherChannel, and what is the rationale to do so?
a) Use L2+L3+L4-based hash, VXLAN VTEPs randomize the source UDP port
b) Use VXLAN deep packet inspection hash, load balancing is not possible otherwise
c) Use L2+L3-based hash, VXLAN VTEPs randomize the source IP address
d) Use L2-based hash, VXLAN VTEPs randomize the source MAC address
Solution
Answer: a
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 7
Refer to the new resource(s) available.
For each of the suggested configuration changes, indicate the event where the
configuration would lead to improved convergence, if any (select all that apply)
Event whose convergence time would be
improved
Configuration change Only a failure of Only a Both failure and
intend to improve a revival of a revival of a router
convergence time router or a link router or a link
link
Decrease Dead interval
Decrease Hello tim
Increase Dead interval
Increase initial SPF delay
Deploy BFD with the
timer/multiplier of 100ms/3
Increase Hello timer
Use point-to -point network type
where possible
Decrease initial SPF delay.
Solution
Event whose convergence time would be
improved
Configuration change Only a failure Only a revival Both failure and
intend to improve of a of a router or a revival of a
convergence time router or a link link router link
Decrease Dead interval √ □ □
Decrease Hello tim □ √ □
Increase Dead interval □ □ □
Increase initial SPF delay □ □ □
Deploy BFD with the √ □ □
timer/multiplier of 100ms/3
Increase Hello timer □ □ □
Use point-to -point network type where □ □ √
possible
Decrease initial SPF delay. □ □ √
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 8
Refer to the new resource(s) available.
This item consists of multiple questions, you may need to scroll down to be able to
see all questions.
8.1 Which two solutions for decreasing the utilization of routing tables in HQ and DC
locations are
applicable in FABD2’s current OSPF design? (Choose two.)
a) Implementing multiple areas
b) Distribute lists
c) Summarization
d) Filter lists
e) Prefix suppression
Solution
Answer: b,e
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
8.2 For every solution intended to control the utilization of the routing tables in
FABD2 HQ and DC,
select the correct characteristics if any. (select all characteristics that apply.)
Characteristics
Solution Controls the In most cases, In most cases, requires
distribution scope of configand- ongoing operational
Type-1/Type-2 LSAs forget maintance
Distribute lists
Implementing
multiple
areas
Summarization
Prefix suppression
Filter lists
Solution
Characteristics
Solution Controls the In most cases, In most cases, requires
distribution scope of configand- ongoing operational
Type-1/Type-2 LSAs forget maintance
Distribute lists □ □ √
Implementing √ √ □
multiple
areas
Summarization □ √ □
Prefix √ √ □
suppression
Filter lists □ □ √
8.3 What are the two disadvantages of using distribute list to control the routing table
contents in
FABD2 HQ and DC? (Choose two.)
a) Incorrect deployment of distribute lists may cause permanent routing loops
b) OSPF link state database contents may become inconsistent
c) SPF algorithm will need more time to complete due to examining LSA contents
against the
distribute list
d) Distribute links in OSPF have no influence on the contents of the CEF FIB on the
router
e) Administrative overhead will grow since distribute lists must be deployed on
all OSPF routers
Solution
Answer: a,e
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 9
Refer to the new resource(s) available.
This item consists of multiple questions, You may need to scroll down to be able to
see all questions.
9.1 Based on current FABD2 design, which switch or switches must perform DHCP
Snooping to avoid
DHCP-related incidents in the HQ?
Solution
Answer: b
9.2 If DHCP Snooping was activated on sw110, what interfaces would need to
operate as trusted
interfaces?
a) Port channels toward sw101 and sw102
b) SVI for management VLAN on sw110
c) SVIs for VLANs where DHCP Snooping is activated
d) Ports toward end hosts
Solution
Answer: a
9.3 Which of the following two approaches can be used to avoid breaking DHCP
functionally when the
DHCP server runs on a different device than the DHCP snooping device? (Choose
two)
a) On IOS based DHCP servers and relay agents, accept DHCP messages
containing Option 82 having all-zero giaddr
b) On switches performing DHCP Snooping, disable Option 82 insertion
c) On DHCP servers, allocate IP addresses to clients based on Option 82 remote-id
and circuit-id values instead of client MAC addresses
d) On DHCP clients, preconfigure customized Option 82 contents
e) On IOS-based DHCP relay agents, change the relay policy to replace Option 82
Solution
Answer: a,b
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 10
Refer to the new resource(s) available.
What are two parallel reasons for the direct spoke-to-spoke DMVPN tunnel coming
up between r62 and
r70? (Choose two)
a) Shortcut switching is enabled on the DMVPN tunnel of r62 and r70
b) The EIGRP next-hop self feature is disabled on r24
c) NHRP Redirects are enabled on the DMVPN tunnel of r24
d) r62’s NHRP and r70’s NHRP registrations can be seen by each other as they are
multicasted over
the same DMVPN tunnel
e) Shortcut switching is enabled on the DMVPN tunnel of r24
f) NHRP Redirects are enabled on the DMVPN tunnel of r62 and r70
Solution
Answer: a,c
QUESTION 11
Refer to the new resource(s) available.
Based on the requirements for the security hardening in Branch #3, what is a viable
solution?
a) Protected ports
b) VLAN ACLs
c) Private VLANs with two independent community secondary VLANs
d) Private VLANs with an isolated secondary VLAN
e) Port ACLs
f) Private VLANs with an isolated and a community secondary VLAN
Solution
Answer: f
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 12
Refer to the new resource(s) available.
Drag the QoS configuration action on the left to the correct device on the right,
observing the correct
order of the configuration. Not all options are used
r24 r70
Create parent QoS policy with 10Mbps shaper 1st Action Action
Create parent QoS policy handling traffic classes 2st Action
Solution
r24 r70
QUESTION 13
Refer to the new resource(s) available.
What change is required to the BGP configuration in the environment of Global SP #1
so that r4 learns
about multiple paths to networks at Branch #3?
a) On r5 and r6, activate the route reflector function
b) On r5 and r6, unique RDs need to be configured
c) On r3 as the route reflector, BGP Multipath feature must be enabled
d) On each PE, unique RTs need to be configured
e) On r4 the BGP maximum paths setting needs to be increased
Solution
Answer: b
QUESTION 14
Refer to the new resource(s) available.
Which two addresses are the best choices for the Connected FABD2 and
RapidStreaming multicast groups?(Choose two.)
a)232.2.1.1
b)232.1.1.1
c)239.129.1.2
d)239.2.1.1
e)232.129.1.1
f)239.1.1.2
g)239.1.1.1
Solution
Answer: d,g
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 15
Refer to the new resource(s) available.
Considering the intended RP design for the High Bandwith multicast range, drag and
drop the appropriate Loop1 configuration on the left to each switch in the diagram. Any
Loop1 configuration can be dropped to multiple switches. Not all options are used
Solution
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 16
Refer to the new resource(s) available.
Considering correct FABD2 design, which two devices are the best choices for
placement of the RP for Low Bandwidth multicast streams?(Choose two.)
a) sw101
b)r11
c) sw102
d)r21
Solution
Answer: a,c
QUESTION 17
Refer to the new resource(s) available.
What prefixes, along with their label bindings must be advertised by LDP in the MPLS
mock lab to enable MPLS L3VPN services?
a) LoopbackO prefixes of all PE routers and prefixes of all infrastructure links
b) LoopbackO prefixes of all PE and P Routers
c) LoopbackO prefixes of all PE routers
d) LoopbackO prefixes of all PE and p routers, and prefixes of all infrastructure links
Solution
Answer: c
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 18
Refer to the new resource(s) available.
What mechanism and type of deployment would be the most appropriate to accomplish
the label filtering goals as requested?
a) OSPF Prefix Suppression enabled globally on PE and P routers
b) OSPF Prefix Suppression enabled on the IT Training Departments 200 loopback
interfaces
c) OSPF Prefix Suppression enabled on the links between PE and P routers
d) LDP advertisement filter applied to P routers
e) LDP advertisement filter applied to PE and P routers
Solution
Answer: e
QUESTION 19
Refer to the new resource(s) available.
What is the proper approach to prevent the MPLS cloud from revealing its internal
infrastructure to the attached endpoints?
a) Egress ACIs placed on PE-CE links
b) MPLS TTL Propagation disabled on PE routers
c) MPLS TTL Propagation disabled on routers
d) ICMP Unreacheables disabled on the Null0 interface on PE and P routers
Solution
Answer: b
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 20
Refer to the new resource(s) available.
Given the description of the issue, which of the following statements would explain the
symptoms described in the e-mail from Travis?
a) The hosts resolved their own hostnames to IPv6 addresses in DNS
b) IPv6 unicast routing was not enabled on sw101
c) The M-flag was not set in Router Advertisements
d) There was no IPv6 IGP running in VLAN 2001
Solution
Answer: c
QUESTION 21
Refer to the new resource(s) available.
Given the description of the issue, what are the two reasons for the absence of RAs
breaking the IPv6
connectivity?(Choose two.)
a) The end hosts considered the IPv6 to be disabled in their network.
b) The end hosts could not locate their default gateway.
c) The sw101 and sw102 switches stopped routing IPv6 traffic on SVI for VLAN
2001.
d) The sw101 and sw102 switches stopped advertising the global prefix on SVI
for VLAN 2001 in EIGRP
e) The end hosts could not locate their DHCPv6 server
f) The end hosts did not have the necessary information for an
autoconfiguration mechanism
Solution
Answer: b,f
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 22
Refer to the new resource(s) available.
What would be the proper approach to meet the security requirement as stated by Travis?
a) Implement IPv6 Secure Neighbor Discovery(SeND)
b) Enable RA Guard
c) Suppress the prefix information in RAS
d) Decrease the frequency of sending out RAs
Solution
Answer: a
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 23
Refer to the new resource(s) available.
23.1 This item consists of multiple questions you may need to scroll down to be able to
see all questions
For each gateway redundancy mechanism, select which characteristics are applicable
on anlOS-based platforms, if any(select all that apply)
HSRP VRRP IPV6 RA
Active role in one instance can control roles in
other instances
Non proprietary mechanism
Active role can be coupled with mechanisms such
as DHCP Relay or IPsec
Support active-active load balancing out of the box
Transparent to end hosts
Can be coupled with BFD
Solution
HSRP VRRP IPV6 RA
Active role in one instance can control roles in √ □ □
other instances
Non proprietary mechanism □ √ √
Active role can be coupled with mechanisms such √ □ □
as DHCP Relay or IPsec
Support active-active load balancing out of the box □ □ √
Transparent to end hosts √ √ □
Can be coupled with BFD √ □ □
23.2 Given Travis preference, what would be the first hop redundancy mechanism of
choice?
a) HSRP or VRRP
b) VRRP or IPV6 RAS
c) HSRP only
d) VRRP only
e) IPv6 RAs only
f) HSRP or IPV6 RAS
Solution
Answer: d
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 24
Refer to the new resource(s) available.
When building the overall SD-WAN policy to meet the Payment Card Industry
requirements for the Point Of Sale(POS) terminals at Branch #1 and Branch #2, what
three steps must be accomplished in vManager?(Choose three.)
a) Create an ACI at Branch #1 and Branch #2 blocking their direct mutual
communication
b) Create POS VPN AND VPN interface feature templates and apply them
to Branch #1 and Branch #2 device templates
c) Apply the policy outbound to the Site IDs of Branch #1 and Branch #2
d) Apply the policy outbound to the Site ID of the DC
e) Create a policy to set the TLOCs for Branch #1 and Branch #2 POS OMP
routers to the DC TLOC(s)
f) Block Branch #1 and Branch #2 from learning each other's TLOC routers
Solution
Answer: b,c,e
QUESTION 25
Refer to the new resource(s) available.
Based on the given constraints and existing design, which two steps can be performed
to provide WAN transport redundancy at Branch #2(Choose two.)
a) On the link between vedge51 and vedge52, create 802.1Q subinterfaces as
necessary and use them as TLOC extensions for each vEdge's transport
b) Add a second physical link between vedge51 and vedge52 and use the links
as TLoc extensions for each extensions for each vEdge's transport
c) Configure a backup default route on each vEdge pointing to the address
of the neighboring vEdge's TLOC extension interface
d) Configure an outbound localized policy on each vEdge to add the TLOC of
the neighboring vEdge to the advertised OMP routes
e) Run OMP between vedge51 and vedge52
Solution
Answer: a,c
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 26
Based on the given constraints and existing design, which two steps can be performed
to ensure that internet-bound traffic from Branch #2 is not sent via the data
center?(Choose two.)
Solution
Answer: a,c
QUESTION 27
Refer to the new resource(s) available.
Which two steps are required to implement the desired Guest VPN design?(Choose two)
a) Implement a localized data policy that blocks Guest VPN traffic between SD-WAN
branches.
b) Configure a centralized VPN membership policy that only allows Guest VPN prefix
to be advertised in OMP.
c) Configure a centralized VPN membership policy that restricts the Guest VPN
prefix from being advertised in OMP.
d) Configure centralized data policy that perform NAT of Guest VPN traffic to
VPN 0.
e) Configure a localized control policy that rewrites the TLOC of Guest VPN routes in
OMP to 0.0.0.0.
Solution
Answer: c,d
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 28
Refer to the new resource(s) available.
Given the intended scope of SDA fabric deployment on Branch #2, which option
represent the smallest applicable IP pool in DNA Center to support LAN Automation
on Branch #2?
a) one/24 subnet
b) one/26 subnet
c) one/27 subnet
d) two/26 subnet
e) one/25 subnet
Solution
Answer:e
QUESTION 29
Refer to the new resource(s) available.
Which option represents the smallest applicable IP pool in DNA Center to support the
planned Layer3VN handoffs on Branch#2?
a) one/25 subnet
b) one/26 subnet
c) one/24 subnet
d) two/26 subnet
Solution
Answer: a
QUESTION 30
Refer to the new resource(s) available.
Which two design options are applicable to provide transit between planned SDA
fabrics in Branch#1
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
Solution
Answer: a,d
QUESTION 31
Refer to the new resource(s) available. Drag the options on the left and drop them in any order into
the two corresponding categories on the right, indicating the best practice where these options
should be added in DNA Center. Not all options are used
DNA Center GUI Workflow DNA Center Template
UDLD Option1 Option1
Anycast GWs Option2 Option2
VTY ACLs Option3 Option3
Spanning Tree(MST) Option4
SNMPv3
TACACS+ Servers
Port Security
Application Policy
Solution
DNA Center GUI Workflow DNA Center Template
Anycast GWs UDLD
SNMPv3 VTY ACLs
TACACS+ Servers Port Security
Spanning Tree(MST) Application Policy
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 32
What are two possible ways of ensuring that authorized local administrators in the Employee VN
on Branch #1 or Branch #2 can still access the local SDA border nodes using their loopback
addresses through in-band SSH access? (Choose two.)
Solution
Answer: a,b
QUESTION 33
Refer to the new resource(s) available. What are the two valid design options for deploying QoS on
the SDA branches that will meet FABD2 requirement? (Choose two.)
a) Extend the existing queuing model into a new 4/5 class model.
b) Use the DNA Center templates to rebuild the QoS policy.
c) Leverage the SGT-based QoS.
d) Use the DNA Center to define business-irrelevant application sets.
e) Use the DNA Center application policy to rebuild the QoS policy.
Solution
Answer: d,e
QUESTION 34
Refer to the new resource(s) available.
Given the requirement, what would be the best way to implement the logging on r21?
a) SNMP poling and processing the results offline
b) Local scripting on the router using a procedural language
c) NETCONF poling and storing results on the routers
d) Use a Python script to access the router CLI remotely through SSH and drive the output collection
Solution
Answer: b
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 35
Refer to the new resource(s) available.
Which are the characteristics of the different scripting method? (For every scripting method, select
all characteristics that apply.)
EEM Python EEM Applet Standard
Policy calling a standard Python script
Python script without EEM
Requires guest shell
Solution
EEM Python EEM Applet Standard
Policy calling a standard Python script
Python script without EEM
Requires guest shell √ √ √
Allows sharing the same Python script □ √ □
for periodic and triggered collection
Allows scheduling a periodic √ √ □
collection run
Allows triggering the collection run on √ √ □
a BGP session event
Allows running the Python script □ □ √
manually outside EEM
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
QUESTION 36
Refer to the new resource(s) available.
Given the circumstances, what is the best option for Anna to develop and debug her scripts before
deploying them on FABD2 production network?
a) Use the production network while executing REST API calls bundled in a transaction and rolled
back at the end without a commit
b) Perform the development and debugging on the production network during dedicated
maintenance windows
c) Create a lab repro for development purposes
d) Use DevNet SD-WAN sandbox labs
Solution
Answer: d
QUESTION 37
Refer to the new resource(s) available.
This item consists of multiple questions you may need to scroll down to be able to see all questions
37.1 What authentication mechanism is used for API calls to vManage?
a) basic HTTP authentication with every API call
b) authentication token in HTTP headers obtained after a call to/auth/token with credentials passed
as HTTP basic authentication
c) client X 509 PKI certificate presented with every API call
d) session cookies obtained after a call to /I_security_check with credentials passed in the
request body
Solution
Answer: d
37.2 What is the nature of the value for the deviceId key for a vEdge?
a) hostname
b) license number
c) device chassis/channel number
d) certificate serial number
Solution
Answer: c
天津新盟教育-华为、思科、Linux 等全套课程腾讯课堂在线培训中心
37.3 What is the purpose of enclosing the deviceIP / deviceId object into square brackets in the
JSON call template?
Solution
Answer: a
QUESTION 38
Refer to the new resource(s) available.
Which two of the following changes to the script would shorten its running time without impairing
its functionality? (Choose two.)
a) Construct the JSON body of the request manually instead of using the json.dumps0 method.
b) Execute the loginAPI0 only once and reuse the session for multiple API calls.
c) Use the put0 method instead of post0 to pass the reboot API call.
d) Combine device IP/ID pairs into a list and pass them all in a single API call.
e) Refer to the vManage by its DNS FQDN instead of its IP address.
Solution
Answer: b,d
QUESTION 39
You have reached the end of exam module 1. Click “End Exam Section” in the main
screen in order to proceed to module 2.